Hi,
I have been using a props.conf file to extract fields in my event logs, but it does not seem to be working. Below are the sample props.conf and event. Any help is much appreciated.
C:\Program Files\SplunkUniversalForwarder\etc\apps\my_app\local\props.conf
[Script:WinService]
EXTRACT-service = SERVICE_NAME: (?\S*)
EXTRACT-state = STATE\s*?: [0-9]\s*(?\S*)
and the event is shown in attached image.
Many thanks in advance.
Regards,
Rajnish Kumar
↧